chore(deps): update terraform vault to v5.10.1 #42

Open
renovate-bot wants to merge 1 commit from renovate/vault-5.x-lockfile into main
Member

This PR contains the following updates:

Package Type Update Change
vault (source) required_provider minor 5.9.0 → 5.10.1

Release Notes

hashicorp/terraform-provider-vault (vault)

v5.10.1

Compare Source

BREAKING CHANGES:

Reverted the 5.10.0 support for pkcs12_bundle and jks_bundle formats in formats in vault_pki_secret_backend_cert, vault_pki_secret_backend_root_cert, vault_pki_secret_backend_root_sign_intermediate, and vault_pki_secret_backend_sign that forced resource recreation. Configurations using these formats or their related arguments are no longer supported. (#​2945)

v5.10.0

Compare Source

FEATURES:

  • New Resource: vault_config_ui_default_auth - Manages UI default authentication configuration for the Vault GUI login form. Controls which authentication methods are displayed by default and as backup options for specific namespaces. Supports inheritance control for child namespaces. Enterprise-only feature requiring Vault 1.20.0+. (#​2846)
  • vault_config_control_group: Added initial implementation for vault_config_control_group resource in sys/config/control-group. (#​2840)
  • New Resource: vault_config_ui_header - Manages custom HTTP headers for the Vault UI. Supports security headers (CSP, HSTS, X-Frame-Options), CORS configuration, and custom organizational headers. Requires Vault 1.16.0+. (#​2842)
  • New Resource: Add support for RADIUS auth backend: vault_radius_auth_backend and vault_radius_auth_backend_user resource and vault_radius_auth_login ephemeral resource.(#​2814)
  • New Resource: vault_activation_flags for managing Vault features that are gated by one-time flags. Requires Vault 1.16 or later. Needs Vault enterprise license(#​2861)
  • New Resource: vault_oauth_resource_server_config_profile for managing OAuth Resource Server Configuration profiles in Vault Enterprise. Enables JWT-based authentication by defining how Vault validates JWT tokens from OAuth 2.0 resource servers. Supports both JWKS-based and static PEM key validation. Requires Vault 2.0.1+. (#​2890)
  • New Resource: vault_agent_registrationfor managing Agent Registry records in Vault Enterprise. Allows registering Vault agents with specific identity entities and configuring ceiling policies that limit maximum agent permissions. Requires Vault 2.0.1+. (#​2885,2935)
  • New Resource: vault_oauth_resource_server_config_profile Add optional_authorization_details to make RAR optional on OAuth resource server and agent registration. Requires Vault 2.0.3+.(#​2930,#​2933)
  • New Resources: vault_userpass_auth_backend_user for user creation, deletion, password updates, and policy updates, and ephemeral resource vault_userpass_auth_login for authenticating with Userpass. (#​2859)
  • Add support for write only parameters for s3 backends for vault_raft_snapshot_agent_config by @​drewmullen ([#​2825]#​2825)
  • vault_transform_transformation: Added mapping_mode, stores and convergent fields to the resource. ([#​2820] #​2820/)
  • New Ephemeral Resource: vault_token for creating Vault tokens with automatic revocation. Supports service and batch tokens, as well as entity alias association, which was not supported in the SDKv2 resource. (#​2877)
  • New Resource: vault_config_group_policy_application - Manages the global group policy application mode for Vault Enterprise. Controls how policies attached to identity groups are applied across namespace boundaries. Supports within_namespace_hierarchy (default) and any modes. Requires Vault Enterprise 1.13.8+. (#​2863)
  • Add support for pkcs12_bundle and jks_bundle formats in vault_pki_secret_backend_cert, vault_pki_secret_backend_root_cert, vault_pki_secret_backend_root_sign_intermediate, and vault_pki_secret_backend_sign (#​2908). Requires Vault 2.1+.
  • vault_policy: Added allow_overwrite to optionally prevent overwriting Vault policies.(#​2895)
  • vault_managed_keys: Added support for usages and max_parallel fields. (#​2887)

IMPROVEMENTS:

  • resource/vault_token: Added deprecation warning to guide users toward the new ephemeral vault_token resource for better security and batch token support. (#​2877)

  • Migrated AWS provider dependency from aws-sdk-go (v1) to aws-sdk-go-v2 for improved performance and maintainability. (#​2882)

  • Replaced backend with mount in vault_aws_access_credentials resource's documentation and improved descriptions for a few other parameters.(#​2911)

  • Updated dependencies:

    • cloud.google.com/go/iam v1.9.0 -> v1.11.0
    • github.com/Azure/azure-sdk-for-go/sdk/azcore v1.21.1 -> v1.22.0
    • github.com/Azure/azure-sdk-for-go/sdk/azidentity v1.13.1 -> v1.14.0
    • github.com/Azure/go-ntlmssp v0.1.0 -> v0.1.1
    • github.com/aws/aws-sdk-go-v2 v1.41.6 -> v1.42.0
    • github.com/aws/aws-sdk-go-v2/service/iam v1.53.8 -> v1.54.5
    • github.com/aws/aws-sdk-go-v2/service/sts v1.42.0 -> v1.43.3
    • github.com/aws/smithy-go v1.25.0 -> v1.27.2
    • github.com/go-sql-driver/mysql v1.9.3 -> v1.10.0
    • github.com/hashicorp/consul/api v1.34.1 -> v1.34.3
    • github.com/hashicorp/terraform-plugin-sdk/v2 v2.40.0 -> v2.40.1
    • github.com/hashicorp/terraform-plugin-testing v1.15.0 -> v1.16.0
    • github.com/hashicorp/vault-plugin-auth-jwt v0.26.1 -> v0.26.3
    • github.com/jackc/pgx/v5 v5.9.1 -> v5.9.2
    • github.com/moby/moby/client v0.4.1 -> v0.5.0
    • github.com/spiffe/go-spiffe/v2 v2.6.0 -> v2.8.1
    • golang.org/x/crypto v0.50.0 -> v0.53.0
    • golang.org/x/net v0.53.0 -> v0.56.0
    • google.golang.org/api v0.276.0 -> v0.286.0
    • google.golang.org/genproto v0.0.0-20260420184626 -> v0.0.0-20260622175928
    • google.golang.org/genproto/googleapis/api v0.0.0-20260414002931 -> v0.0.0-20260618152121
    • google.golang.org/genproto/googleapis/rpc v0.0.0-20260610212136 -> v0.0.0-20260618152121
    • k8s.io/utils v0.0.0-20260319190234 -> v0.0.0-20260617174310

Configuration

📅 Schedule: (in timezone Europe/Amsterdam)

  • Branch creation
    • At any time (no schedule defined)
  • Automerge
    • At any time (no schedule defined)

🚦 Automerge: Disabled by config. Please merge this manually once you are satisfied.

♻ Rebasing: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox.

🔕 Ignore: Close this PR and you won't be reminded about these updates again.


  • If you want to rebase/retry this PR, check this box

This PR has been generated by Mend Renovate.

This PR contains the following updates: | Package | Type | Update | Change | |---|---|---|---| | [vault](https://search.opentofu.org/provider/hashicorp/vault) ([source](https://github.com/hashicorp/terraform-provider-vault)) | required_provider | minor | `5.9.0` → `5.10.1` | --- ### Release Notes <details> <summary>hashicorp/terraform-provider-vault (vault)</summary> ### [`v5.10.1`](https://github.com/hashicorp/terraform-provider-vault/blob/HEAD/CHANGELOG.md#5101-June-26-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-vault/compare/v5.10.0...v5.10.1) BREAKING CHANGES: Reverted the 5.10.0 support for `pkcs12_bundle` and `jks_bundle` formats in formats in `vault_pki_secret_backend_cert`, `vault_pki_secret_backend_root_cert`, `vault_pki_secret_backend_root_sign_intermediate`, and `vault_pki_secret_backend_sign` that forced resource recreation. Configurations using these formats or their related arguments are no longer supported. ([#&#8203;2945](https://github.com/hashicorp/terraform-provider-vault/pull/2945)) ### [`v5.10.0`](https://github.com/hashicorp/terraform-provider-vault/blob/HEAD/CHANGELOG.md#5100-June-23-2026) [Compare Source](https://github.com/hashicorp/terraform-provider-vault/compare/v5.9.0...v5.10.0) FEATURES: - **New Resource**: `vault_config_ui_default_auth` - Manages UI default authentication configuration for the Vault GUI login form. Controls which authentication methods are displayed by default and as backup options for specific namespaces. Supports inheritance control for child namespaces. Enterprise-only feature requiring Vault 1.20.0+. ([#&#8203;2846](https://github.com/hashicorp/terraform-provider-vault/pull/2846)) - `vault_config_control_group`: Added initial implementation for `vault_config_control_group` resource in sys/config/control-group. ([#&#8203;2840](https://github.com/hashicorp/terraform-provider-vault/pull/2840)) - **New Resource**: `vault_config_ui_header` - Manages custom HTTP headers for the Vault UI. Supports security headers (CSP, HSTS, X-Frame-Options), CORS configuration, and custom organizational headers. Requires Vault 1.16.0+. ([#&#8203;2842](https://github.com/hashicorp/terraform-provider-vault/pull/2842)) - **New Resource**: Add support for RADIUS auth backend: `vault_radius_auth_backend` and `vault_radius_auth_backend_user` resource and `vault_radius_auth_login` ephemeral resource.([#&#8203;2814](https://github.com/hashicorp/terraform-provider-vault/pull/2814)) - **New Resource**: `vault_activation_flags` for managing Vault features that are gated by one-time flags. Requires Vault 1.16 or later. Needs Vault enterprise license([#&#8203;2861](https://github.com/hashicorp/terraform-provider-vault/pull/2861/)) - **New Resource**: `vault_oauth_resource_server_config_profile` for managing OAuth Resource Server Configuration profiles in Vault Enterprise. Enables JWT-based authentication by defining how Vault validates JWT tokens from OAuth 2.0 resource servers. Supports both JWKS-based and static PEM key validation. Requires Vault 2.0.1+. ([#&#8203;2890](https://github.com/hashicorp/terraform-provider-vault/pull/2890)) - **New Resource**: `vault_agent_registration`for managing Agent Registry records in Vault Enterprise. Allows registering Vault agents with specific identity entities and configuring ceiling policies that limit maximum agent permissions. Requires Vault 2.0.1+. ([#&#8203;2885](https://github.com/hashicorp/terraform-provider-vault/pull/2885),[2935](https://github.com/hashicorp/terraform-provider-vault/pull/2935)) - **New Resource**: `vault_oauth_resource_server_config_profile` Add optional\_authorization\_details to make RAR optional on OAuth resource server and agent registration. Requires Vault 2.0.3+.([#&#8203;2930](https://github.com/hashicorp/terraform-provider-vault/pull/2930),[#&#8203;2933](https://github.com/hashicorp/terraform-provider-vault/pull/2933)) - **New Resources**: `vault_userpass_auth_backend_user` for user creation, deletion, password updates, and policy updates, and ephemeral resource `vault_userpass_auth_login` for authenticating with Userpass. ([#&#8203;2859](https://github.com/hashicorp/terraform-provider-vault/pull/2859)) - Add support for write only parameters for s3 backends for `vault_raft_snapshot_agent_config` by [@&#8203;drewmullen](https://github.com/drewmullen) (\[[#&#8203;2825](https://github.com/hashicorp/terraform-provider-vault/issues/2825)][#&#8203;2825](https://github.com/hashicorp/terraform-provider-vault/pull/2825)) - `vault_transform_transformation`: Added `mapping_mode`, `stores` and `convergent` fields to the resource. (\[[#&#8203;2820](https://github.com/hashicorp/terraform-provider-vault/issues/2820)] [#&#8203;2820/](https://github.com/hashicorp/terraform-provider-vault/pull/2820/)) - **New Ephemeral Resource**: `vault_token` for creating Vault tokens with automatic revocation. Supports service and batch tokens, as well as entity alias association, which was not supported in the SDKv2 resource. ([#&#8203;2877](https://github.com/hashicorp/terraform-provider-vault/pull/2877)) - **New Resource**: `vault_config_group_policy_application` - Manages the global group policy application mode for Vault Enterprise. Controls how policies attached to identity groups are applied across namespace boundaries. Supports `within_namespace_hierarchy` (default) and `any` modes. Requires Vault Enterprise 1.13.8+. ([#&#8203;2863](https://github.com/hashicorp/terraform-provider-vault/pull/2863)) - Add support for `pkcs12_bundle` and `jks_bundle` formats in `vault_pki_secret_backend_cert`, `vault_pki_secret_backend_root_cert`, `vault_pki_secret_backend_root_sign_intermediate`, and `vault_pki_secret_backend_sign` ([#&#8203;2908](https://github.com/hashicorp/terraform-provider-vault/pull/2908)). Requires Vault 2.1+. - `vault_policy`: Added `allow_overwrite` to optionally prevent overwriting Vault policies.([#&#8203;2895](https://github.com/hashicorp/terraform-provider-vault/pull/2895)) - `vault_managed_keys`: Added support for `usages` and `max_parallel` fields. ([#&#8203;2887](https://github.com/hashicorp/terraform-provider-vault/pull/2887/)) IMPROVEMENTS: - `resource/vault_token`: Added deprecation warning to guide users toward the new ephemeral `vault_token` resource for better security and batch token support. ([#&#8203;2877](https://github.com/hashicorp/terraform-provider-vault/pull/2877)) - Migrated AWS provider dependency from `aws-sdk-go` (v1) to `aws-sdk-go-v2` for improved performance and maintainability. ([#&#8203;2882](https://github.com/hashicorp/terraform-provider-vault/pull/2882)) - Replaced backend with mount in `vault_aws_access_credentials` resource's documentation and improved descriptions for a few other parameters.([#&#8203;2911](https://github.com/hashicorp/terraform-provider-vault/pull/2911)) - Updated dependencies: - `cloud.google.com/go/iam` v1.9.0 -> v1.11.0 - `github.com/Azure/azure-sdk-for-go/sdk/azcore` v1.21.1 -> v1.22.0 - `github.com/Azure/azure-sdk-for-go/sdk/azidentity` v1.13.1 -> v1.14.0 - `github.com/Azure/go-ntlmssp` v0.1.0 -> v0.1.1 - `github.com/aws/aws-sdk-go-v2` v1.41.6 -> v1.42.0 - `github.com/aws/aws-sdk-go-v2/service/iam` v1.53.8 -> v1.54.5 - `github.com/aws/aws-sdk-go-v2/service/sts` v1.42.0 -> v1.43.3 - `github.com/aws/smithy-go` v1.25.0 -> v1.27.2 - `github.com/go-sql-driver/mysql` v1.9.3 -> v1.10.0 - `github.com/hashicorp/consul/api` v1.34.1 -> v1.34.3 - `github.com/hashicorp/terraform-plugin-sdk/v2` v2.40.0 -> v2.40.1 - `github.com/hashicorp/terraform-plugin-testing` v1.15.0 -> v1.16.0 - `github.com/hashicorp/vault-plugin-auth-jwt` v0.26.1 -> v0.26.3 - `github.com/jackc/pgx/v5` v5.9.1 -> v5.9.2 - `github.com/moby/moby/client` v0.4.1 -> v0.5.0 - `github.com/spiffe/go-spiffe/v2` v2.6.0 -> v2.8.1 - `golang.org/x/crypto` v0.50.0 -> v0.53.0 - `golang.org/x/net` v0.53.0 -> v0.56.0 - `google.golang.org/api` v0.276.0 -> v0.286.0 - `google.golang.org/genproto` v0.0.0-20260420184626 -> v0.0.0-20260622175928 - `google.golang.org/genproto/googleapis/api` v0.0.0-20260414002931 -> v0.0.0-20260618152121 - `google.golang.org/genproto/googleapis/rpc` v0.0.0-20260610212136 -> v0.0.0-20260618152121 - `k8s.io/utils` v0.0.0-20260319190234 -> v0.0.0-20260617174310 </details> --- ### Configuration 📅 **Schedule**: (in timezone Europe/Amsterdam) - Branch creation - At any time (no schedule defined) - Automerge - At any time (no schedule defined) 🚦 **Automerge**: Disabled by config. Please merge this manually once you are satisfied. ♻ **Rebasing**: Whenever PR becomes conflicted, or you tick the rebase/retry checkbox. 🔕 **Ignore**: Close this PR and you won't be reminded about these updates again. --- - [ ] <!-- rebase-check -->If you want to rebase/retry this PR, check this box --- This PR has been generated by [Mend Renovate](https://github.com/renovatebot/renovate). <!--renovate-debug:eyJjcmVhdGVkSW5WZXIiOiI0My4yNDAuMCIsInVwZGF0ZWRJblZlciI6IjQzLjI0OS4wIiwidGFyZ2V0QnJhbmNoIjoibWFpbiIsImxhYmVscyI6WyJyZW5vdmF0ZSJdfQ==-->
renovate-bot force-pushed renovate/vault-5.x-lockfile from f2328f4f78 to 9e31035e5d 2026-06-24 09:09:10 +00:00 Compare
renovate-bot force-pushed renovate/vault-5.x-lockfile from 9e31035e5d to 2e8abaae73 2026-06-25 15:12:18 +00:00 Compare
renovate-bot force-pushed renovate/vault-5.x-lockfile from 2e8abaae73 to af016e2c39 2026-06-26 12:09:23 +00:00 Compare
renovate-bot changed title from chore(deps): update terraform vault to v5.10.0 to chore(deps): update terraform vault to v5.10.1 2026-06-26 12:09:25 +00:00
renovate-bot force-pushed renovate/vault-5.x-lockfile from 10529a3fb6 to 6c91d95eb3 2026-07-14 09:10:49 +00:00 Compare
renovate-bot force-pushed renovate/vault-5.x-lockfile from 6c91d95eb3 to 6a43a623d5 2026-07-15 00:10:41 +00:00 Compare
renovate-bot force-pushed renovate/vault-5.x-lockfile from 6a43a623d5 to 113b72b899 2026-07-16 03:10:49 +00:00 Compare
renovate-bot force-pushed renovate/vault-5.x-lockfile from 113b72b899 to f94c5a8a56 2026-07-16 18:12:43 +00:00 Compare
This pull request can be merged automatically.
You are not authorized to merge this pull request.
View command line instructions

Checkout

From your project repository, check out a new branch and test the changes.
git fetch -u origin renovate/vault-5.x-lockfile:renovate/vault-5.x-lockfile
git switch renovate/vault-5.x-lockfile

Merge

Merge the changes and update on Forgejo.

Warning: The "Autodetect manual merge" setting is not enabled for this repository, you will have to mark this pull request as manually merged afterwards.

git switch main
git merge --no-ff renovate/vault-5.x-lockfile
git switch renovate/vault-5.x-lockfile
git rebase main
git switch main
git merge --ff-only renovate/vault-5.x-lockfile
git switch renovate/vault-5.x-lockfile
git rebase main
git switch main
git merge --no-ff renovate/vault-5.x-lockfile
git switch main
git merge --squash renovate/vault-5.x-lockfile
git switch main
git merge --ff-only renovate/vault-5.x-lockfile
git switch main
git merge renovate/vault-5.x-lockfile
git push origin main
Sign in to join this conversation.
No reviewers
No labels
No milestone
No project
No assignees
1 participant
Notifications
Due date
The due date is invalid or out of range. Please use the format "yyyy-mm-dd".

No due date set.

Dependencies

No dependencies set

Reference
toot.community/platform!42
No description provided.